Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    WebGUI access from WAN

    webGUI
    8
    12
    87.2k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      shdwdrgn
      last edited by

      I have a dynamic DNS service set to point to to my router so I can host a webpage behind it.  I have the NAT rules setup so requests on port 80 are sent to the computer, however everytime I try to see if it is working, it just asks me to log into my pfsense box.  I'm not sure if this is because I am trying it from internal, but I would assume it is trying to make the connection by going out and then back in 9I haven't setup NAT reflection yet).  i would really like to prevent access to the webGUI from the WAN port and want to make sure the website will be accessable.

      Thank you.

      1 Reply Last reply Reply Quote 0
      • GruensFroeschliG
        GruensFroeschli
        last edited by

        try setting the webgui to another port.
        system –> general setup

        We do what we must, because we can.

        Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

        1 Reply Last reply Reply Quote 0
        • D
          databeestje
          last edited by

          put the webgui on a alternate port.

          Then create a firewall rule on the wan interface from any to wan address webgui port.

          That should do it.

          1 Reply Last reply Reply Quote 0
          • S
            shdwdrgn
            last edited by

            That fixed the problem with not being able to access the webserver.  Thanks very much.

            One other question.  is it possible to block access to the webgui from the WAN port completely?  if so, how?  or do you just have to set it to a random unused port?

            What's the recommendation from the experts?

            1 Reply Last reply Reply Quote 0
            • D
              databeestje
              last edited by

              If there is no rule to allow traffic to the webgui port on the wan interface it wil not be accesible.

              Everything not expressly permitted is denied per default.

              1 Reply Last reply Reply Quote 0
              • S
                shdwdrgn
                last edited by

                Gotcha.  I'll make sure to set it to a port that won't be used for anything else and then ensure that there is no rule setup for it on the WAN port.

                1 Reply Last reply Reply Quote 0
                • A
                  akanawa
                  last edited by

                  access from WAN

                  What rule should I write, and how exactly should I write it if I wish to allow access from the wan port?

                  1 Reply Last reply Reply Quote 0
                  • S
                    sai
                    last edited by

                    @akanawa:

                    access from WAN

                    What rule should I write, and how exactly should I write it if I wish to allow access from the wan port?

                    To allow access the pfSense Web Configurator from the WAN (or Internet):

                    make a new rule ->

                    Interface: WAN

                    Source ip : any (its better to restrict this if you know where you will be accessing from)
                    Source port: any

                    Dest Ip: WAN Interface
                    Dest port : the port that the web gui works on, as set in the General Settings

                    :)

                    1 Reply Last reply Reply Quote 0
                    • A
                      akanawa
                      last edited by

                      @sai:

                      @akanawa:

                      access from WAN

                      What rule should I write, and how exactly should I write it if I wish to allow access from the wan port?

                      To allow access the pfSense Web Configurator from the WAN (or Internet):

                      make a new rule ->

                      Interface: WAN

                      Source ip : any (its better to restrict this if you know where you will be accessing from)
                      Source port: any

                      Dest Ip: WAN Interface
                      Dest port : the port that the web gui works on, as set in the General Settings

                      :)

                      Thank you

                      I'll have to offsite later, too see if it worked

                      1 Reply Last reply Reply Quote 0
                      • S
                        shreckbull
                        last edited by

                        Why, pfsense developpers, don't create a little function for enable/disable WAN access with a form "EN/DISABLE button" and with, if configuration not good, a form for create SSL certificat AND select an other port (not 80/443) …

                        ???

                        Or if a developper, like this concept, why not developpe a package ... ?

                        I think itsn't complicated to do ...

                        1 Reply Last reply Reply Quote 0
                        • S
                          sullrich
                          last edited by

                          No thanks.  This option is not useful and would only clutter the interface.  Add a firewall rule to permit the traffic.

                          1 Reply Last reply Reply Quote 0
                          • jahonixJ
                            jahonix
                            last edited by

                            @shreckbull:

                            Why, pfsense developpers, don't create a little function for enable/disable WAN access with a form "EN/DISABLE button"

                            You already have this.
                            On the WAN rules page hit the green permit button left of the rule and it gets light green. This means it's disabled. Hit it again to re-enable.

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.